NVISOsecurity / DLLoaderLinks
☆24Updated 5 years ago
Alternatives and similar repositories for DLLoader
Users that are interested in DLLoader are comparing it to the libraries listed below
Sorting:
- Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH☆62Updated 4 years ago
- Enabled / Disable LSA Protection via BYOVD☆74Updated 3 years ago
- ☆50Updated 3 years ago
- A tool that bypasses Windows Defender by manually loading DLLs, parsing EAT directly, and updating IAT with unhooked functions to run M…☆22Updated last year
- Get your data from the resource section manually, with no need for windows apis☆64Updated 10 months ago
- Tool for playing with Windows Access Token manipulation.☆55Updated 2 years ago
- This script is used to unload PsSetCreateProcessNotifyRoutineEx, PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine and PsSetCr…☆63Updated last year
- Simple and sane cryptographic wrapper library.☆33Updated 2 years ago
- DLL Hollowing PoC - Remote and Self shellcode injection☆81Updated 3 years ago
- Writeup of Payload Techniques in C involving Mutants, Session 1 -> Session 0 migration, and Self-Deletion of payloads.☆127Updated 3 years ago
- Patch AMSI and ETW in remote process via direct syscall☆83Updated 3 years ago
- abusing Process Hacker driver to terminate other processes (BYOVD)☆83Updated 2 years ago
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆69Updated last year
- A PoC project for embedding shellcode to Hint/Name Table☆110Updated 3 years ago
- Halos Gate-based NTAPI Unhooker☆51Updated 3 years ago
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space☆124Updated 2 years ago
- Process Injection: APC Injection☆32Updated 4 years ago
- Custom implementation of DbgHelp's MiniDumpWriteDump function. Uses static syscalls to replace low-level functions like NtReadVirtualMemo…☆124Updated 3 years ago
- Building and Executing Position Independent Shellcode from Object Files in Memory☆158Updated 4 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆101Updated 2 years ago
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆56Updated last year
- Beacon Object File allowing creation of Beacons in different sessions.☆81Updated 3 years ago
- ☆56Updated 2 years ago
- Unhooks Bit Defender from NTDLL and KERNELBASE using a classic technique.☆56Updated 2 years ago
- Win32 keylogger that supports all (non-ime using) languages correctly☆51Updated last year
- It stinks☆102Updated 3 years ago
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆38Updated 2 years ago
- Herpaderply Hollowing - a PE injection technique, hybrid between Process Hollowing and Process Herpaderping☆63Updated 2 years ago
- This program is used to perform reflective DLL Injection to a remote process specified by the user.☆66Updated 2 years ago
- ☆62Updated 3 years ago